Domain Control Validation (DCV) Reuse Periods

The CA/Browser Forum has approved a phased reduction in how long Domain Control Validation (DCV) can be reused before it must be completed again. Previously, Domain Control Validation (DCV) could be reused for up to 398 days. From March 15, 2026, the maximum reuse period reduces to 200 days.

This means that every time you reissue an SSL Certificate, your existing Domain Control Validation (DCV) must still be within its reuse window. If your Domain Control Validation (DCV) has expired, you will need to complete the validation process again before your SSL Certificate can be issued or reissued.

Important : The SSL Certificate products offered by Trustico® carry a maximum validity of 200 days in line with industry requirements. Sectigo, the Certificate Authority (CA) that issues these SSL Certificates, enforces a Domain Control Validation (DCV) reuse period of 198 days beginning March 12, 2026. In practice, this means your Domain Control Validation (DCV) may need to be completed slightly sooner than the 200-day maximum suggests.

This change applies to all Domain Control Validation (DCV) methods equally, including approver e-mail, Domain Name System (DNS) validation, and file-based authentication. It does not matter which method you originally used to validate your domain. If the reuse period has expired, you will need to complete Domain Control Validation (DCV) again using any supported method. Learn About File-Based Authentication 🔗

Any existing Domain Control Validation (DCV) record that is older than 198 days will no longer be eligible for SSL Certificate issuance or reissuance from March 12, 2026. This applies even if your original 398-day reuse window has not yet expired. Customers who completed Domain Control Validation (DCV) before September 2025 should expect to revalidate when they next reissue.

Future Reductions to Domain Control Validation (DCV) Reuse

The reduction to 200 days is the first phase. Further reductions are scheduled in the years ahead. From March 15, 2027, the Domain Control Validation (DCV) reuse period will reduce to 100 days. From March 15, 2029, it will reduce to just 10 days.

As these reuse periods shorten, completing Domain Control Validation (DCV) will become a more frequent part of managing your SSL Certificates. Trustico® is building tools including Application Programming Interface (API) access and expiry notification services to help customers and partners stay ahead of these changes. Learn About The Trustico® Validation Procedure 🔗

Most Popular Questions

Learn about the changes to Domain Control Validation (DCV) reuse periods, including the reduction from 398 days to 200 days effective March 15, 2026, and how this affects SSL Certificate issuance and reissuance through Trustico® products.

What is a Domain Control Validation (DCV) reuse period?

A Domain Control Validation (DCV) reuse period is the length of time your completed domain validation remains valid for SSL Certificate issuance or reissuance. During this window, you do not need to complete Domain Control Validation (DCV) again when reissuing an SSL Certificate against the same domain.

How long can Domain Control Validation (DCV) be reused from March 2026?

From March 15, 2026, the maximum Domain Control Validation (DCV) reuse period reduces from 398 days to 200 days. The SSL Certificate products offered by Trustico® carry a maximum validity of 200 days in line with this industry requirement. Sectigo, the Certificate Authority (CA) that issues these SSL Certificates, enforces a reuse period of 198 days beginning March 12, 2026.

Does this change affect all Domain Control Validation (DCV) methods?

Yes. The reduced reuse period applies equally to all Domain Control Validation (DCV) methods, including approver e-mail, Domain Name System (DNS) validation, and file-based authentication. It does not matter which method was originally used to validate your domain.

What happens to my existing Domain Control Validation (DCV) on March 12, 2026?

Any existing Domain Control Validation (DCV) record that is older than 198 days will no longer be eligible for SSL Certificate issuance or reissuance from March 12, 2026. This applies even if your original 398-day reuse window has not yet expired. Customers who completed Domain Control Validation (DCV) before September 2025 should expect to revalidate when they next reissue.

Will the Domain Control Validation (DCV) reuse period continue to shorten?

Yes. From March 15, 2027, the Domain Control Validation (DCV) reuse period will reduce to 100 days. From March 15, 2029, it will reduce to just 10 days. These reductions are part of a phased schedule approved by the CA/Browser Forum.

Do I need to complete Domain Control Validation (DCV) every time I reissue an SSL Certificate?

Only if your previous Domain Control Validation (DCV) has expired. If your Domain Control Validation (DCV) is still within its reuse window, you can reissue without completing it again. As reuse periods shorten, Domain Control Validation (DCV) will need to be completed more frequently.

Why is Sectigo enforcing this change on March 12 instead of March 15?

Sectigo has chosen to begin enforcement on March 12, 2026, three days ahead of the CA/Browser Forum deadline of March 15, 2026. This is an operational decision by Sectigo as the Certificate Authority (CA). In practice, this means Domain Control Validation (DCV) reuse is limited to 198 days rather than the 200-day maximum set by the CA/Browser Forum.

Is Trustico® building tools to help manage more frequent Domain Control Validation (DCV)?

Yes. Trustico® is developing Application Programming Interface (API) access and expiry notification services that will help customers and partners track both SSL Certificate expiration dates and Domain Control Validation (DCV) reuse periods. These tools are actively in development.

Ask Trustico® Assistant

For Instant Answers - Start Here When You Have a Question or Need Help

SSL Certificate Validity Periods Are Changing to 200 Days

SSL Certificate Validity Periods Are Changing t...

The reduction in SSL Certificate validity periods is driven by the need to regularly confirm that the Certificate holder is still entitled to use the SSL Certificate. No new Certificate...

SSL Certificate Validity Periods Are Changing t...

The reduction in SSL Certificate validity periods is driven by the need to regularly confirm that the Certificate holder is still entitled to use the SSL Certificate. No new Certificate...

SSL Certificate Works on WWW but Not Root Domain : Troubleshooting Guide

SSL Certificate Works on WWW but Not Root Domai...

Several server configuration problems can cause SSL Certificates to work on the www version but fail on the non-www version of a domain. Understanding these causes helps identify the specific...

SSL Certificate Works on WWW but Not Root Domai...

Several server configuration problems can cause SSL Certificates to work on the www version but fail on the non-www version of a domain. Understanding these causes helps identify the specific...

Understanding SSL Certificate File Formats and Extensions

Understanding SSL Certificate File Formats and ...

SSL Certificate files can be broadly categorized into three main types based on how the data is encoded and stored. Understanding these categories will help you identify which format you...

Understanding SSL Certificate File Formats and ...

SSL Certificate files can be broadly categorized into three main types based on how the data is encoded and stored. Understanding these categories will help you identify which format you...

Understanding the AutoCSR Service for SSL Certificate Orders

Understanding the AutoCSR Service for SSL Certi...

Learn how AutoCSR works, compare it to hosting company practices, find out when automated credential generation is appropriate versus generating your own CSR. Covers security considerations including the Trustico® non-retention...

Understanding the AutoCSR Service for SSL Certi...

Learn how AutoCSR works, compare it to hosting company practices, find out when automated credential generation is appropriate versus generating your own CSR. Covers security considerations including the Trustico® non-retention...

What Is Encrypted Server Name Indication (ESNI)? How Encrypted Client Hello (ECH) Protects Your Privacy

What Is Encrypted Server Name Indication (ESNI)...

The limitations of Encrypted Server Name Indication (ESNI) led to its evolution into Encrypted Client Hello (ECH) in 2020. Encrypted Client Hello (ECH) addresses the shortcomings of its predecessor while...

What Is Encrypted Server Name Indication (ESNI)...

The limitations of Encrypted Server Name Indication (ESNI) led to its evolution into Encrypted Client Hello (ECH) in 2020. Encrypted Client Hello (ECH) addresses the shortcomings of its predecessor while...

Transport Layer Security (TLS) and Cybersecurity

Transport Layer Security (TLS) and Cybersecurity

Every time a browser connects to a website using Hypertext Transfer Protocol Secure (HTTPS), Transport Layer Security (TLS) encrypts the connection to protect data from interception and tampering.

Transport Layer Security (TLS) and Cybersecurity

Every time a browser connects to a website using Hypertext Transfer Protocol Secure (HTTPS), Transport Layer Security (TLS) encrypts the connection to protect data from interception and tampering.

1 / 6